Junglewise Threat Intelligence

CVE-2026-40791: WP Time Slots Booking Form unauthenticated XSS

CVE-2026-40791 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: CodePeople.

Executive brief

The WP Time Slots Booking Form plugin for WordPress, which allows websites to manage appointment scheduling, contains a security flaw that allows unauthenticated attackers to inject malicious scripts. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could execute code in their browser. This can lead to unauthorized actions, theft of session information, or the display of fraudulent content on the website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the WP Time Slots Booking Form plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires user interaction, typically from a privileged user clicking a malicious link or visiting a crafted page. Successful exploitation can result in the execution of scripts in the context of the victim's browser, potentially leading to session hijacking or site defacement. The issue is resolved in version 1.2.47.

Affected products

  • CodePeople WP Time Slots Booking Form <= 1.2.46

Timeline

  • 2026-03-24: other: Reported by Daniel Wade
  • 2026-04-23: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: NVD published date
  • 2026-04-23: patched: Version 1.2.47 released

References

Related threats